Conversation

Jarkko Sakkinen

The single biggest issue in confidential computing is still. that there is no legit way to deliver cryptographic proof to client/browser inherited from CPU attestation. i.e. a x509 certificate. and so that it is vendor-neutral. not sure if even @signalapp can do this. who cares what you run in the backend if you cannot prove it.
2
0
0

Jarkko Sakkinen

Edited 6 months ago
@signalapp like for instance: https://signal.org/blog/building-faster-oram/. none of this applies unless proven otherwise for every single running instance of the client. or if you have a belief system applied.
1
0
0
@signalapp also e.g. signal would benefit in qa if there was emulated infrastructure in place (my previous post). not that well tested except field tested ofc.
0
0
0
@signalapp in linux. (once we add x509 support for TPM2, probably 6.11) the CPU certificate delivery could be even delivered with a public key coming from TPM (private key non-existent in the machine). So you could hardware-to-hardware pipeline.
0
0
1